pub struct WindowsHandleTable<'a, Driver>{ /* private fields */ }os-windows only.Expand description
A Windows handle table.
A handle table in Windows tracks handles to kernel objects for a specific process, allowing access control and management.
§Implementation Details
Corresponds to _HANDLE_TABLE.
Implementations§
Source§impl<'a, Driver> WindowsHandleTable<'a, Driver>
impl<'a, Driver> WindowsHandleTable<'a, Driver>
Sourcepub fn new(
vmi: VmiState<'a, WindowsOs<Driver>>,
va: Va,
) -> WindowsHandleTable<'a, Driver>
pub fn new( vmi: VmiState<'a, WindowsOs<Driver>>, va: Va, ) -> WindowsHandleTable<'a, Driver>
Creates a new Windows module object.
Sourcepub fn table_code(&self) -> Result<u64, VmiError>
pub fn table_code(&self) -> Result<u64, VmiError>
Sourcepub fn next_handle_needing_pool(&self) -> Result<u64, VmiError>
pub fn next_handle_needing_pool(&self) -> Result<u64, VmiError>
Sourcepub fn iter(
&self,
) -> Result<impl Iterator<Item = Result<(u64, WindowsHandleTableEntry<'a, Driver>), VmiError>> + use<'a, Driver>, VmiError>
pub fn iter( &self, ) -> Result<impl Iterator<Item = Result<(u64, WindowsHandleTableEntry<'a, Driver>), VmiError>> + use<'a, Driver>, VmiError>
Iterates over all handle table entries.
Returns an iterator over all handle table entries that have a valid object pointer. The iterator yields a tuple containing the handle value and the handle table entry.
§Implementation Details
The functionality is similar to the Windows kernel’s internal
ExpSnapShotHandleTables() function.
Examples found in repository?
176fn enumerate_handle_table(process: &WindowsProcess<Driver>) -> Result<(), VmiError> {
177 const OBJ_PROTECT_CLOSE: u32 = 0x00000001;
178 const OBJ_INHERIT: u32 = 0x00000002;
179 const OBJ_AUDIT_OBJECT_CLOSE: u32 = 0x00000004;
180
181 static LABEL_PROTECTED: [&str; 2] = ["", " (Protected)"];
182 static LABEL_INHERIT: [&str; 2] = ["", " (Inherit)"];
183 static LABEL_AUDIT: [&str; 2] = ["", " (Audit)"];
184
185 // Get the handle table from `_EPROCESS.ObjectTable`.
186 let handle_table = match process.handle_table() {
187 Ok(Some(handle_table)) => handle_table,
188 Ok(None) => {
189 println!(" (No handle table)");
190 return Ok(());
191 }
192 Err(err) => {
193 tracing::error!(%err, "Failed to get handle table");
194 return Ok(());
195 }
196 };
197
198 // Iterate over `_HANDLE_TABLE_ENTRY` items.
199 for handle_entry in handle_table.iter()? {
200 let (handle, entry) = match handle_entry {
201 Ok(entry) => entry,
202 Err(err) => {
203 println!("Failed to get handle entry: {}", handle_error(err)?);
204 continue;
205 }
206 };
207
208 let attributes = match entry.attributes() {
209 Ok(attributes) => attributes,
210 Err(err) => {
211 println!("Failed to get attributes: {}", handle_error(err)?);
212 continue;
213 }
214 };
215
216 let granted_access = match entry.granted_access() {
217 Ok(granted_access) => granted_access,
218 Err(err) => {
219 println!("Failed to get granted access: {}", handle_error(err)?);
220 continue;
221 }
222 };
223
224 let object = match entry.object() {
225 Ok(Some(object)) => object,
226 Ok(None) => {
227 // [`WindowsHandleTable::iter`] should only return entries with
228 // valid objects, so this should not happen.
229 println!("<NULL>");
230 continue;
231 }
232 Err(err) => {
233 println!("Failed to get object: {}", handle_error(err)?);
234 continue;
235 }
236 };
237
238 let type_name = match object.type_name() {
239 Ok(type_name) => type_name,
240 Err(err) => handle_error(err)?,
241 };
242
243 let full_path = match object.full_path() {
244 Ok(Some(path)) => path,
245 Ok(None) => String::from("<no-path>"),
246 Err(err) => handle_error(err)?,
247 };
248
249 println!(
250 " {:04x}: Object: {:x} GrantedAccess: {:08x}{}{}{} Entry: {}",
251 handle,
252 object.va().0,
253 granted_access,
254 LABEL_PROTECTED[((attributes & OBJ_PROTECT_CLOSE) != 0) as usize],
255 LABEL_INHERIT[((attributes & OBJ_INHERIT) != 0) as usize],
256 LABEL_AUDIT[((attributes & OBJ_AUDIT_OBJECT_CLOSE) != 0) as usize],
257 entry.va(),
258 );
259
260 println!(" Type: {type_name}, Path: {full_path}");
261 }
262
263 Ok(())
264}Sourcepub fn lookup(
&self,
handle: u64,
) -> Result<Option<WindowsHandleTableEntry<'a, Driver>>, VmiError>
pub fn lookup( &self, handle: u64, ) -> Result<Option<WindowsHandleTableEntry<'a, Driver>>, VmiError>
Performs a lookup in the handle table to find the address of a handle table entry.
Implements the multi-level handle table lookup algorithm used by Windows. Returns the virtual address of the handle table entry.
§Implementation Details
The functionality is similar to the Windows kernel’s internal
ExpLookupHandleTableEntry() function.
Trait Implementations§
Source§impl<Driver> VmiVa for WindowsHandleTable<'_, Driver>
impl<Driver> VmiVa for WindowsHandleTable<'_, Driver>
Auto Trait Implementations§
impl<'a, Driver> !Freeze for WindowsHandleTable<'a, Driver>
impl<'a, Driver> !RefUnwindSafe for WindowsHandleTable<'a, Driver>
impl<'a, Driver> !Send for WindowsHandleTable<'a, Driver>
impl<'a, Driver> !Sync for WindowsHandleTable<'a, Driver>
impl<'a, Driver> !UnwindSafe for WindowsHandleTable<'a, Driver>
impl<'a, Driver> Unpin for WindowsHandleTable<'a, Driver>
impl<'a, Driver> UnsafeUnpin for WindowsHandleTable<'a, Driver>
Blanket Implementations§
Source§impl<T> ArchivePointee for T
impl<T> ArchivePointee for T
Source§type ArchivedMetadata = ()
type ArchivedMetadata = ()
Source§fn pointer_metadata(
_: &<T as ArchivePointee>::ArchivedMetadata,
) -> <T as Pointee>::Metadata
fn pointer_metadata( _: &<T as ArchivePointee>::ArchivedMetadata, ) -> <T as Pointee>::Metadata
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> LayoutRaw for T
impl<T> LayoutRaw for T
Source§fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>
fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>
Source§impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
Source§unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool
unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool
Source§fn resolve_niched(out: Place<NichedOption<T, N1>>)
fn resolve_niched(out: Place<NichedOption<T, N1>>)
out indicating that a T is niched.